Backdoor

Backdoor.MokesRI.S16788718 (file analysis)

Malware Removal

The Backdoor.MokesRI.S16788718 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MokesRI.S16788718 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Backdoor.MokesRI.S16788718?


File Info:

crc32: F865B47E
md5: 25352832326051f359a4e86b7e448135
name: 25352832326051F359A4E86B7E448135.mlw
sha1: 4f1655b90e588c9c5821c3061607c633ce9da544
sha256: 80bbc85f7e35c961ddc8284d380e53c07a0bd594bc8bf865d1d536a81f5361c0
sha512: eefde3e12531e174fc3bbaacef83a0f86c10b27719f53440b1fa3ed269528b488c2ec063a20ae3531c00320af8a4079ab2ad9bbfe8692e6fb7726b8451f3d0da
ssdeep: 6144:BoaHN8mosrtpDeSZL0mUDYYIVz05GYBl9Yn/YfmdnaxVAbXCg6GpnDZ2m+MWB:uaHN8B4pampY+YBlSPbXZF2ZMY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0147 0x01ed

Backdoor.MokesRI.S16788718 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00571fb61 )
LionicTrojan.Win32.Zenpak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.57833
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.MokesRI.S16788718
ALYacTrojan.GenericKDZ.71069
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2607387
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDropper:Win32/Bunitu.d1b787de
K7GWTrojan ( 00571fb61 )
Cybereasonmalicious.232605
CyrenW32/Kryptik.CGZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHBV
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Generickdz-9785960-0
KasperskyHEUR:Trojan.Win32.Zenpak.pef
BitDefenderTrojan.GenericKDZ.71069
NANO-AntivirusTrojan.Win32.Zenpak.ibehzw
MicroWorld-eScanTrojan.GenericKDZ.71069
Ad-AwareTrojan.GenericKDZ.71069
SophosMal/Generic-S
ComodoMalware@#ndf0axmak063
BitDefenderThetaGen:NN.ZexaF.34126.CqW@amWlwuTG
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.Win32.GLUPTEBA.SMTH.hp
McAfee-GW-EditionBehavesLike.Win32.Emotet.gc
FireEyeGeneric.mg.25352832326051f3
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.StellarStealer.paztv
eGambitUnsafe.AI_Score_97%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.OT!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Zenpak
GDataTrojan.GenericKDZ.71069
AhnLab-V3Trojan/Win32.Glupteba.R354440
Acronissuspicious
McAfeeLockbit-FSWW!253528323260
MAXmalware (ai score=87)
VBA32Trojan.Zenpak
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.GLUPTEBA.SMTH.hp
RisingTrojan.Kryptik!1.CE1D (CLASSIC)
YandexTrojan.Zenpak!6ggBURaSIQw
IkarusTrojan-Spy.MSIL.Agent
FortinetW32/CoinMiner.HHGA!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Backdoor.MokesRI.S16788718?

Backdoor.MokesRI.S16788718 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment